As published in American Bankers Association (ABA) Risk and Compliance
For many years, compliance professionals viewed the Home Mortgage Disclosure Act (HMDA) and Regulation B through separate operational lenses. HMDA was viewed as a data collection and reporting requirement, while Regulation B (which implements the Equal Credit Opportunity Act) was considered the primary fair lending regulation governing prohibited-basis discrimination, credit underwriting, and notification requirements. Each had its own workflows, controls, and specialists. That division may have been practical once; however, it no longer reflects how compliance risk actually works.
Advances in data analytics, the introduction of Section 1071, and growing expectations around fair lending governance have changed the compliance landscape: data and decision-making can no longer be separated. Instead, they are increasingly part of one compliance architecture — one in which lending process, documentation, notices, reported data, governance, and technology must work together. When they do not, weaknesses that once looked technical can quickly become fair lending, operational, and reputational problems.
Financial institutions (FIs) are increasingly being asked not only whether they are making fair credit decisions, but whether they can prove it: Is the data supporting those decisions accurate, complete, and capable of demonstrating fairness?
The evolution of fair lending oversight
When HMDA was enacted in 1975, its primary purpose was transparency. Policymakers wanted better visibility into whether FIs were serving the housing needs of their communities. In 1989, Congress effectively broadened HMDA’s purpose by adding data on race, ethnicity, and sex of borrowers. Regulation B addressed a different but related concern: whether applicants were treated fairly. It established rules designed to ensure that applicants receive fair and equitable treatment throughout the credit process.
Historically, one regulation focused on information while the other focused on behavior. Modern compliance programs, however, have increasingly recognized that outcomes and decisions cannot be evaluated independently from the data used to measure them. Fair lending risk management now depends as much on the quality of information as it does on the quality of decision-making.
Section 1071 reinforces this trend. By requiring covered FIs to collect and report small business lending data, the requirement expands the concept that transparency is a critical component of fairness.
The result is a compliance environment where governance, data quality, fair lending analysis, and business practices are more interconnected than ever before.
For years, many FIs treated HMDA as a reporting exercise. Teams focused on filing requirements, edit checks, submission deadlines, and annual reporting obligations. Success was often measured by the accuracy of the final submission. However, successful programs do not stop there. The same data collected for regulatory reporting should be used internally by FIs to understand lending performance and gaps, identify trends, assess community needs, and evaluate customer outcomes.
In other words, HMDA data has evolved from a compliance obligation into a strategic asset. The same will likely occur with Section 1071 data. FIs investing significant resources in small business lending data collection may discover that the information provides insight extending beyond regulatory reporting. Patterns involving application volume, approval rates, product utilization, geographic reach, and customer demographics can help management better understand both opportunities and risks within its markets.
Organizations that view these datasets solely as regulatory requirements may miss their broader value as useful information to drive business decisions and strategy.
Fair lending is an enterprise issue
Historically, fair lending was often viewed as a specialized regulatory function. Today, it touches virtually every area of a financial institution. Business lines influence marketing strategies and product design. Operations personnel shape application intake processes and customer interactions. Technology teams manage the systems that capture, transfer, and store critical data. Model risk and analytics professionals oversee automated decisioning tools. Compliance staff monitor adherence to regulations and challenge results. Internal audit and risk management assess whether the control environment is working effectively.
Fair lending risk management now depends as much on the quality of information as it does on the quality of decision-making.”
In this interconnected environment, success depends less on any individual department and more on coordination across the organization. HMDA, Regulation B, and Section 1071 all reinforce this. Each requires contributions from multiple stakeholders, and weaknesses in one area can quickly affect another.
That shift matters because many significant compliance failures no longer begin with an obvious policy violation. They begin with fragmentation. A system field is mapped incorrectly. A workflow differs by channel. A denial reason supported in one system does not match the reason disclosed to the applicant. An application is coded as withdrawn because it is operationally convenient but technically incorrect. Together, these issues can distort management reporting, weaken fair lending analysis, and create doubt about whether the institution fully understands its own lending outcomes.
The growing importance of data governance
Data governance has become a foundational compliance issue. It is the basis for trend analysis, risk monitoring, management reporting, adverse action support, and regulatory credibility. Poor data quality often signals broader operational weaknesses. The data oversight conversation is no longer limited to whether a field was entered correctly, but instead management is asking more fundamental questions:
- How reliable is our data?
- Where does information originate?
- Who owns the data?
- How are changes controlled?
- What processes ensure accuracy?
Consider monitoring information (race, ethnicity, and sex). Errors in monitoring information can significantly impact fair lending analysis. Retail, online, and broker workflows may not collect information the same way or at the same point in the application process. Online applications may not request monitoring information early enough to ensure it is collected and accurately reported if the application is later withdrawn, denied, or closed for incompleteness. What looks like a workflow issue can quickly become a fair lending issue when data gaps limit the institution’s ability to evaluate outcomes reliably across prohibited basis groups.
Application outcomes present similar challenges. If action taken codes are inaccurate, fair lending analysis will be distorted. Increased reliance on automated decisioning can increase these errors if system mapping is flawed. Two common examples are using “withdrawn” as a catch-all outcome when an applicant goes silent, and reporting an application as closed for incompleteness when more specific reasons for denial exist. Not only are these practices technical compliance issues, they also may obscure patterns in lending outcomes and complicate efforts to assess whether similarly situated applicants are being treated consistently.
Denial reasons are also receiving increased attention because their impact extends beyond credit underwriting to customer disclosures and data integrity. Denial reasons documented in an institution’s loan origination system do not always align with reasons reported on adverse action notices or on the HMDA Loan Application Register (LAR). Adverse action notices are intended to inform applicants of the specific reasons why credit was denied and provide enough clarity for applicants to understand what affected their credit eligibility. For FIs, accurately documenting the principal reasons for denial helps demonstrate that credit decisions were grounded in documented underwriting factors rather than bias, habit, or system issues. The underwriting documentation, adverse action notice, and data reported on the LAR must be consistent.
The consistency challenge becomes more pronounced as underwriting becomes more automated. Automated underwriting systems, decision engines, and artificial intelligence models may influence or drive credit decisions, but they do not reduce an institution’s obligation to identify and communicate specific principal reasons for adverse action. Complexity in the model is not a substitute for clarity in compliance. If an institution cannot explain how a denial reason was determined, why it was selected, or whether that reason is consistent across systems and disclosures, it has a governance issue, regardless of how sophisticated the technology used to make the credit decision may be.
Lessons from HMDA for Section 1071
FIs preparing for Section 1071 do not need to start from scratch. The better approach is to build on the disciplines already embedded in effective HMDA programs. Both frameworks require consistent data definitions, effective collection processes, employee training, quality control, validation, and meaningful management reporting.
Most importantly, both HMDA and Section 1071 compliance require FIs to think carefully about the relationship between reported data and actual business practices. Organizations with HMDA compliance already integrated into their governance structures should already have much of the foundation needed for Section 1071 compliance.
The challenge is less about creating entirely new programs and more about extending existing disciplines into another lending segment. This includes establishing clear ownership, implementing robust controls, providing detailed training, and ensuring that management receives meaningful information regarding performance and emerging risks.
Technology is reshaping governance
Technology is reshaping the intersection of HMDA, Regulation B, and Section 1071.
Automated underwriting systems, machine learning applications, and advanced analytics offer tremendous opportunities to improve consistency and efficiency, but they also increase the need for disciplined governance. FIs must understand what data influences decisions, how decision logic is applied, where overrides occur, and whether outcomes align with policy, risk appetite, and fair lending expectations. The question is no longer whether a single credit decision complied with a policy, but whether the system as a whole produces outcomes the institution can explain and defend.
As FIs continue to adopt advanced technologies, transparency and explainability will remain critical considerations. Consumers want confidence that credit decisions are fair. Communities want confidence that FIs are serving their markets responsibly. Boards want confidence that key risks are understood and managed, and management teams want confidence that the information used to monitor performance is reliable. Transparency supports each of those objectives. The collection and reporting of lending data create visibility into outcomes, while fair lending requirements help ensure those outcomes are reached through equitable processes. Together, they form a framework for accountability and trust. FIs that treat transparency as a management value rather than merely a regulatory obligation are often better positioned to sustain compliance over time.
What FIs should do now
For compliance leaders, the practical implication is straightforward: stop managing HMDA and Regulation B in silos. FIs should evaluate whether application data, underwriting processes, adverse action notices, and reported fields are consistent across the lending lifecycle. They should review details such as how monitoring information is captured across channels and products, how action-taken codes are assigned and denial reasons are mapped, and how changes to systems or models are governed. They should also ensure that ownership is clear, not just for filing the LAR, but for data retention, control design, exception management, and issue escalation. These are the disciplines that turn technical compliance into credible governance.
Conclusion
The future of compliance will be increasingly data-driven. FIs that understand the connection between fair treatment and reliable information will perform best. HMDA transformed mortgage lending by introducing greater transparency into the home financing process and Section 1071 is poised to bring similar visibility to small business lending. Regulation B continues to provide the principles that guide fair and equitable treatment across the credit lifecycle.
Viewed individually, each regulation carries distinct requirements. Viewed collectively, however, they demonstrate a broader trend. FIs must demonstrate that they comply with rules and regulations, and moreover, that they understand their lending outcomes, maintain accurate data, and uphold governance structures capable of supporting responsible decision-making.
For compliance professionals, this demand presents both a challenge and an opportunity. The challenge lies in managing increasingly complex data, systems, and regulatory expectations. The opportunity lies in helping organizations build stronger governance, improve decision-making, and foster greater trust among customers, communities, and stakeholders.
September/October 2026
Learn More
- Explore CrossCheck’s fair lending consulting services
- Subscribe to HMDA Hub
- Read From Automated Underwriting to AI: How Fair Lending Risk Oversight Must Evolve


